CVE-2025-30086

Aliases:GHSA-h27m-3qw8-3pw8GO-2025-3826
Advisory lineage Upstream: 0 Downstream: 1
Deferred
Published: 25 Jul 2025, 00:00
Last modified:25 Jul 2025, 15:07

Vulnerability Summary

Overall Risk (default)
low
20/100
CVSS Score
4.9 MEDIUM
v3.1 (cve.org)
EPSS Score
0.39% LOW
0% probability +0.34%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Jul 2025, 00:00
Published
Vulnerability first disclosed
25 Jul 2025, 15:07
Last Modified
Vulnerability information updated

Description

CNCF Harbor 2.13.x before 2.13.1 and 2.12.x before 2.12.4 allows information disclosure by administrators who can exploit an ORM Leak present in the /api/v2.0/users endpoint to leak users' password hash and salt values. The q URL parameter allows a user to filter users by any column, and filter password=~ could be abused to leak out a user's password hash character by character. An attacker with administrator access could exploit this to leak highly sensitive information stored in the Harbor database. All endpoints that support the q URL parameter are vulnerable to this ORM leak attack.

CVSS Metrics

  • v3.1MEDIUMScore: 4.9CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.39% Percentile: 60%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • github.com/goharborharbor

    ≥ 2.13.0, < 2.13.1 | ≥ 2.4.0-rc1.1, < 2.12.4 | < 2.4.0-rc1.0.20250331071157-dce7d9f5cffb | ≥ 2.13.0+incompatible, < 2.13.1+incompatible

References (9)